Archived topic
DISALLOW_FILE_EDIT is defined. You should also disallow PHP execution in GP Hoo
3 replies · Started by Jos on March 16, 2018
Hi Tom or Leo,
I built several websites using your great theme. But I still get the message DISALLOW_FILE_EDIT is defined. You should also disallow PHP execution in GP Hooks. I already edited the wp-config file.
Like this:
define('DISALLOW_FILE_EDIT', TRUE); // Sucuri Security: Wed, 14 Dec 2016 11:30:13 +0000
define( 'GENERATE_HOOKS_DISALLOW_PHP', true );
But I still get the message. I read some posts about it. Sometimes there is stated that you can hide the message.
What I want to know is: what is the risk if disallow php in Hooks is false? Is there a security issue?
Thanks in advance!
Jos
Hi there,
This article should explain all of it: https://docs.generatepress.com/article/disallow-php-execution/
Let us know if anything is unclear :)
Yes Leo,
It's unclear to me if it's a security risk? If it is not why there is this message?
Greets,
Jos
See the last few paragraphs in Tom's reply here: https://generatepress.com/forums/topic/hostgator-finding-malware-on-gp-premium/#post-404557